Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 241

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
USDA Secretary Brooke Rollins sent Easter email to staff touting 'Jesus' and 'God'
FedEx trucking spinoff targets 2026 operating margin of 12%
Playing Alphabet using a bullish options trade after tech giant recently topped a key level
Countries around the world are considering teen social media bans – why experts warn it’s a ‘lazy’ fix
ICE agents shoot man in California after he 'weaponized' vehicle, DHS says
Trump praises Hungary PM Viktor Orbán after Vance calls him at Budapest rally
AWS teams working around the clock to keep Middle East services up after drone strikes, CEO says
Queer for Fear: The History of Queer Horror: Queer for Fear: The History of Queer Horror
Ray Dalio: Trump-Xi meeting to focus on trade, capital flows
JD Vance calls Iran ceasefire a 'fragile truce' and says Trump is 'impatient to make progress'